Sceawere

Vulnerability Detail

CVE-2026-101016UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDMARC Improper Input Handling Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Trusted Domain Project
Product
OpenDMARC
Attack Type
Handling of Exceptional Conditions
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to handling of exceptional conditions. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T09:17:05.340Z",
  "pubdate": "2026-09-28T09:17:05.340Z",
  "executiveSummary": "A critical vulnerability exists within the Trusted Domain Project OpenDMARC library (versions up to 1.4.2) related to the improper handling of policy parameters during the parsing phase. The vulnerability resides in the opendmarc_policy_parse_dmarc function within libopendmarc/opendmarc_policy.c.\nThe flaw allows remote, unauthenticated attackers to trigger an exceptional condition by supplying maliciously crafted DMARC policy tags. By manipulating specific arguments—specifically fo, rf, ri, pct, sp, adkim, aspf, rua, and ruf—an attacker can induce unexpected behavior in the application logic.\nThis vulnerability is particularly severe because the exploit has been disclosed publicly, potentially increasing the risk of widespread exploitation. Successful manipulation could result in service disruption or other impacts related to the improper handling of exceptional conditions. As the vendor has not provided a responsive update, organizations currently utilizing OpenDMARC 1.4.2 or earlier are at risk of remote exploitation. The primary risk implication is the compromise of mail authentication processing, which could potentially be leveraged to bypass intended policy enforcement mechanisms or cause denial-of-service conditions in mail transfer agent (MTA) architectures relying on this library.",
  "technicalDetails": "The vulnerability is localized to the opendmarc_policy_parse_dmarc function, which is responsible for parsing DMARC (Domain-based Message Authentication, Reporting, and Conformance) records. These records are typically retrieved via DNS lookups for specific domains. The function, located in libopendmarc/opendmarc_policy.c, is designed to iterate through policy tags and assign values to corresponding internal data structures.\nThe root cause of this vulnerability is improper validation of input data when processing the optional tags: 'fo' (failure options), 'rf' (reporting format), 'ri' (reporting interval), 'pct' (percentage), 'sp' (subdomain policy), 'adkim' (DKIM alignment mode), 'aspf' (SPF alignment mode), 'rua' (aggregate report URI), and 'ruf' (failure report URI). The parsing logic fails to adequately sanitize or verify the format and contents of these tags before attempting to process them as legitimate policy parameters.\nExploitation occurs when a remote attacker causes a DNS query to return a malicious or malformed DMARC record. Because the parsing function does not properly manage the transition between expected and exceptional conditions, the library may enter an unstable state when encountering these specially crafted strings. An attacker can craft a DNS response containing arbitrary or malformed data within these tags, forcing the library's parser to misinterpret the data, which may lead to memory corruption, improper control flow, or process termination.\nThe attack flow is initiated when a target server performs a DNS request for the _dmarc record of an attacker-controlled domain. The attacker provides a crafted response that triggers the vulnerability upon execution of opendmarc_policy_parse_dmarc. The lack of robust input boundary checks and error handling within this function means that unexpected characters or oversized values in the mentioned tags are not discarded, but rather processed through logic that does not anticipate such malformed inputs.\nThe impact is significant due to the library's role in security enforcement. If the parsing logic crashes or handles the input erroneously, the MTA may be forced to either fail open (disabling DMARC protections) or fail closed (causing a denial of service). Given that the exploit code is publicly available, an attacker can reliably trigger the vulnerable code path to achieve these outcomes remotely without the need for prior authentication or elevated privileges."
}
CVE-2026-101016: OpenDMARC Improper Input Handling Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere